Overview
The NIA Data Linkage Disclosure Review process establishes guidelines that researchers must follow when requesting file transfers.
To preserve the confidentiality of research participants found in the NIA-funded Cohorts linked with CMS data, all file transfer requests within the LINKAGE Enclave must undergo independent disclosure limitation review by the LINKAGE Team and each NIA-funded Study.
Please note, each NIA-funded Study develops individualized policies for file transfers disclosure review which may differ from the NIA Data Linkage Disclosure Review process. In the case of conflicting guidelines, the most conservative disclosure review process will be followed.
Definitions
“Personally Identifiable Information” or “PII” refers to information which can be used to distinguish or trace an individual's identity, such as their name, social security number, biometric records, etc., alone, or when combined with other personal or identifying information which is linked or linkable to a specific individual [HHS Policy and Plan for Preparing for and Responding to a Breach of Personally Identifiable Information (PII) (June 29, 2017)].
“Protected Health Information” or “PHI” means individually identifiable health information as defined in the HIPAA Privacy Rule at 45 CFR § 160.103.
“User” refers to any approved user of the enclave with permissions to import or export files from the enclave. This is inclusive of all Study and Researcher team members.
Roles and Responsibilities
Users will:
- Abide by the terms and conditions as set forth in the NIA Data Use Agreement.
- Read and agree to Security Policy when logging into the enclave. The banner advises users that any mishandling of the enclave system and/or sensitive information contained therein could result in (1) a $250,000 fine; (2) up to 10 years of jail; and (3) termination of employment.
NIA Data Linkage Contractor will:
- Maintain the File Auditing and Security Tool (FAST), an algorithmic tool that automatically reviews all file transfers upon submission. FAST preliminarily scans all files for common PII format, small cells, executable files, and other information. File transfers are subsequently quarantined for manual review (PII, small cells) or rejected (executable files).
- Conduct a manual review of all file transfer requests to ensure the polices as outlined in this document are followed.
NIA Federal Staff will:
- Provide oversight of the file transfer request disclosure process.
NIA-funded Study Compliance Officer will:
- Conduct a manual review of all file transfer requests to ensure the study’s disclosure polices are followed.
Frequently Asked Questions
Visit our page on Frequently Asked Questions on the LINKAGE Program to learn more the disclosure review and file transfer process.
File Import Request Process
- All file transfer requests will go through an automated file transfer review which occurs upon file submission. This data security algorithm screens for PII, small cells, and other information.
- The file transfer requests are then queued for manual review by the NIA Data Linkage Contractor and the NIA-funded Study providing data access.
- The User may request an unlimited number of files for importation into the enclave. While there is no limit on the number of files that may be imported, all files requested for import must have clear connections to the approved research plan.
- The NIA Data Linkage Contractor will review the file transfer(s) during routine business hours but may take up to one business day to complete their review.
- Each NIA-funded Study reviews the file transfer requests as designated in their disclosure review protocol.
- Due to differing disclosure review protocols between LINKAGE and the NIA-funded Study, the most restrictive protocol will prevail.
- The following data/file types are eligible for transfer into the enclave. Please note that all files must have a clear connection to the approved research plan.:
- CMS Public Use Files (PUFs) and documentation
*
- Other publicly available files and documentation
*
- Code files
*
- Other file types will be individually considered for importation
- CMS Public Use Files (PUFs) and documentation
The following data/file types may not be transferred into the enclave:
- Research Identifiable Files (RIFs) and Limited Data Sets (LDS) obtained directly from the Centers for Medicare and Medicaid Services (CMS)
*
- Sensitive data sets obtained through a data use agreement (DUA) with another entity (e.g., federal agency, academic institution, or commercial organization) may only be transferred into the enclave with written permission from the entity providing access to the data
*
- Research Identifiable Files (RIFs) and Limited Data Sets (LDS) obtained directly from the Centers for Medicare and Medicaid Services (CMS)
*The NIA-funded Study may have more restrictive guidelines for file transfer requests.
Requirements for exporting files
Clearly label all values with a description and label all columns, and clearly identify the sample size used for the analysis.
- Clearly label any provider- or facility-level zip codes as provider zip codes.
- Suppress or recategorize all cells related to beneficiary or patient information with a frequency < 11 or frequency limited by the study (whichever is greater). Before submitting, users should consider recategorizing the variables instead of removing the observations completely. If this is not possible, identify and suppress all cells with frequencies < 11 (or greater if specified by study) before resubmitting the output. NOTE: Output containing zero cell frequencies/counts are acceptable to output.
- Use age categories and ranges instead of specific ages or percentiles.
- Ensure health information, including counts of beneficiaries identified by diagnosis or cause of death codes, meet minimum sample size criteria for release.
- Remove individual-level (PII/PHI) data from any output.
- Avoid including beneficiary dates of care, including admission dates and discharge dates.
- Exclude extreme values, e.g., remove proc univariate extreme observations (1, 99, and 100 percentiles).
- Exclude beneficiary-level geographic information at the zip code level.
- Limit file sizes to less than 1 GB.
- Avoid using zip files in file exports.
File Export Request Process
- All file transfer requests will go through an automated file transfer review which occurs upon file submission. This data security algorithm screens for PII, small cells, and other information.
- The file transfer requests are then queued for manual review by the NIA Data Linkage Contractor and the NIA-funded Study providing data access.
- The NIA Data Linkage Contractor will review the file transfer(s) during routine business hours but may take up to one full business day to complete their review.
- Transfers must be presentation/publication-ready, including titles, sample sizes, variable definitions, tables, and frequencies.
- No intermediate results will be approved for transfer, such results should be viewed in the enclave by authorized team members. Outbound files must be aggregate summary data with no cell sizes <11.
- Users must clearly label values, suppress or recategorize small cells, use age ranges, and remove PII/PHI and extreme values.
Exportation of code is limited to 10 times per year or during the closeout of the study – all code exports must exclude file paths and PII/PHI before submission.
- For faster output review, submit code and logs with a program interface or copy into a text file format.
DBSR